-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathleaf-2-a
374 lines (293 loc) · 7.91 KB
/
leaf-2-a
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
!Command: show running-config
!Running configuration last done at: Sat Jul 22 02:47:38 2023
!Time: Sat Jul 22 03:33:31 2023
version 10.3(1) Bios:version
hostname leaf-2-a
policy-map type network-qos jumboframes
class type network-qos class-default
mtu 9216
vdc leaf-2-a id 1
limit-resource vlan minimum 16 maximum 4094
limit-resource vrf minimum 2 maximum 4096
limit-resource port-channel minimum 0 maximum 511
limit-resource m4route-mem minimum 58 maximum 58
limit-resource m6route-mem minimum 8 maximum 8
cfs eth distribute
nv overlay evpn
feature ospf
feature bgp
feature pim
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature lacp
feature vpc
feature nv overlay
no password strength-check
username admin password 5 $5$OEILEO$ExR9klwglqRDRl2LVronZR5FqDDWhEYbjjp9gIdd.Z5
role network-admin
username cisco password 5 $5$MDDNEI$6chZ4X0y7zWdJq2u10wcB39YZzsnZzqFQNZ89qatAj.
role network-admin
username cisco passphrase lifetime 99999 warntime 14 gracetime 3
ip domain-lookup
system qos
service-policy type network-qos jumboframes
copp profile strict
snmp-server user admin network-admin auth md5 3208E8B9D356C3462CAEC0C8F989BC4F88
82 priv aes-128 174CEB9FA77FE27D11C789CBED849B54C083 localizedV2key
snmp-server user cisco network-admin auth md5 176CB6D4F22FB7750FDEF1DFF4DED00483
9A priv aes-128 2174C5D8ED75804E39F6C699FE8A94228F9D localizedV2key
rmon event 1 log trap public description FATAL(1) owner PMON@FATAL
rmon event 2 log trap public description CRITICAL(2) owner PMON@CRITICAL
rmon event 3 log trap public description ERROR(3) owner PMON@ERROR
rmon event 4 log trap public description WARNING(4) owner PMON@WARNING
rmon event 5 log trap public description INFORMATION(5) owner PMON@INFO
fabric forwarding anycast-gateway-mac 0000.dead.beef
ip pim rp-address 10.255.0.123 group-list 239.0.0.0/8
ip pim ssm range 232.0.0.0/8
vlan 1,60-70,100,444,555
vlan 60
name ops
vn-segment 10060
vlan 61
name sales
vn-segment 10061
vlan 100
name public1
vn-segment 10100
vlan 444
name BACKUP_VLAN_ROUTING_VPC
vlan 555
name L3VNI-For-IRB
vn-segment 10555
spanning-tree port type edge bpduguard default
spanning-tree loopguard default
spanning-tree vlan 60-61,100,555 priority 8192
route-map DIRECT-PERMIT-ALL permit 10
description ** Route-Map for BGP to redist route **
vrf context ISP
vni 10555
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
address-family ipv6 unicast
route-target both auto
route-target both auto evpn
vrf context management
vpc domain 1
peer-switch
role priority 10
peer-keepalive destination 172.30.0.42 source 172.30.0.41
delay restore 90
peer-gateway
delay restore interface-vlan 30
ipv6 nd synchronize
ip arp synchronize
interface Vlan1
no ip redirects
no ipv6 redirects
interface Vlan100
description ** Anycast Gateway For Public **
no shutdown
mtu 9216
vrf member ISP
no ip redirects
ip address 69.25.124.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface Vlan444
description ** Underlay Backup over vPC Peer-Link **
no shutdown
no ip redirects
ip address 192.168.2.1/30
no ipv6 redirects
ip ospf authentication-key 3 fa3ab8e90610229c
ip ospf network point-to-point
ip router ospf UNDERLAY-NET area 0.0.0.0
ip pim sparse-mode
interface Vlan555
description ** L3VNI-For-IRB **
no shutdown
mtu 9216
vrf member ISP
no ip redirects
ip forward
no ipv6 redirects
interface port-channel3
switchport access vlan 60
speed 1000
vpc 3
interface port-channel999
description ** vPC Peer-Link **
switchport mode trunk
switchport trunk allowed vlan 60-61,100,444,555
spanning-tree port type network
vpc peer-link
interface nve1
no shutdown
description ** VTEP/NVE Interface **
host-reachability protocol bgp
source-interface loopback1
member vni 10060
mcast-group 239.1.1.1
member vni 10061
mcast-group 239.1.1.1
member vni 10100
mcast-group 239.1.1.100
member vni 10555 associate-vrf
interface Ethernet1/1
description ** Spine-1 **
no switchport
mtu 9216
medium p2p
ip unnumbered loopback0
ip ospf authentication-key 3 fa3ab8e90610229c
ip ospf network point-to-point
ip router ospf UNDERLAY-NET area 0.0.0.0
ip pim sparse-mode
no shutdown
interface Ethernet1/2
description ** Spine-2 **
no switchport
mtu 9216
medium p2p
ip unnumbered loopback0
ip ospf authentication-key 3 fa3ab8e90610229c
ip ospf network point-to-point
ip router ospf UNDERLAY-NET area 0.0.0.0
ip pim sparse-mode
no shutdown
interface Ethernet1/3
description *** Linux Server ***
switchport access vlan 60
speed 1000
channel-group 3 mode active
interface Ethernet1/4
interface Ethernet1/5
interface Ethernet1/6
interface Ethernet1/7
interface Ethernet1/8
interface Ethernet1/9
interface Ethernet1/10
interface Ethernet1/11
interface Ethernet1/12
interface Ethernet1/13
interface Ethernet1/14
interface Ethernet1/15
interface Ethernet1/16
interface Ethernet1/17
interface Ethernet1/18
interface Ethernet1/19
interface Ethernet1/20
interface Ethernet1/21
interface Ethernet1/22
interface Ethernet1/23
interface Ethernet1/24
interface Ethernet1/25
interface Ethernet1/26
interface Ethernet1/27
interface Ethernet1/28
interface Ethernet1/29
interface Ethernet1/30
interface Ethernet1/31
interface Ethernet1/32
interface Ethernet1/33
interface Ethernet1/34
interface Ethernet1/35
interface Ethernet1/36
interface Ethernet1/37
interface Ethernet1/38
interface Ethernet1/39
interface Ethernet1/40
interface Ethernet1/41
interface Ethernet1/42
interface Ethernet1/43
interface Ethernet1/44
interface Ethernet1/45
interface Ethernet1/46
interface Ethernet1/47
interface Ethernet1/48
interface Ethernet1/49
interface Ethernet1/50
interface Ethernet1/51
interface Ethernet1/52
interface Ethernet1/53
interface Ethernet1/54
interface Ethernet1/55
interface Ethernet1/56
interface Ethernet1/57
interface Ethernet1/58
interface Ethernet1/59
interface Ethernet1/60
interface Ethernet1/61
interface Ethernet1/62
interface Ethernet1/63
description ** vPC Peer-Link **
switchport mode trunk
switchport trunk allowed vlan 60-61,100,444,555
channel-group 999 mode active
interface Ethernet1/64
description ** vPC Peer-Link **
switchport mode trunk
switchport trunk allowed vlan 60-61,100,444,555
channel-group 999 mode active
interface mgmt0
vrf member management
ip address 172.30.0.41/24
interface loopback0
description ** RID/BGP Overlay **
ip address 10.255.1.21/32
ip router ospf UNDERLAY-NET area 0.0.0.0
ip pim sparse-mode
interface loopback1
description ** VTEP/Overlay **
ip address 10.255.255.21/32
ip address 10.255.255.20/32 secondary
ip ospf authentication-key 3 fa3ab8e90610229c
ip router ospf UNDERLAY-NET area 0.0.0.0
ip pim sparse-mode
icam monitor scale
cli alias name wr copy running-config startup-config
line console
line vty
boot nxos bootflash:/nxos64-cs.10.3.1.F.bin
router ospf UNDERLAY-NET
router-id 10.255.1.21
log-adjacency-changes
area 0.0.0.0 authentication
router bgp 65001
router-id 10.255.1.21
log-neighbor-changes
template peer VXLAN_SPINE
remote-as 65001
update-source loopback0
address-family ipv4 unicast
address-family l2vpn evpn
send-community
send-community extended
neighbor 10.255.0.1
inherit peer VXLAN_SPINE
description ** iBGP Peer to Spine-1 **
neighbor 10.255.0.2
inherit peer VXLAN_SPINE
description ** iBGP Peer to Spine-2 **
vrf ISP
log-neighbor-changes
address-family ipv4 unicast
redistribute direct route-map DIRECT-PERMIT-ALL
address-family ipv6 unicast
redistribute direct route-map DIRECT-PERMIT-ALL
evpn
vni 10060 l2
rd auto
route-target import auto
route-target export auto
vni 10061 l2
rd auto
route-target import auto
route-target export auto
vni 10100 l2
rd auto
route-target import auto
route-target export auto